nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-27236 CVE-2025-27236
LOW
User information disclosure via api_jsonrpc.php on method user.get with param search
Record summary
CVE-2025-27236 has a selected CVSS score of 2.1 (low).
Description
A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 3, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ZabbixBrowse Zabbix / ZabbixDefault status: unknown | CVE List | 6.0.38 to ≤ 6.0.40 | affected |
| 7.0.9 to ≤ 7.0.16 | affected | ||
| 7.2.3 to ≤ 7.2.10 | affected | ||
| 7.4.0 to < 7.4.1 | affected |
References
2support.zabbix.com
https://support.zabbix.com/browse/ZBX-27060